US9705850B2

Enabling comparable data access control for lightweight mobile devices in clouds

Summary by NHIP

Constant-size ciphertext policy encryption

The method stores encrypted data in a computer system by generating keys based on user IDs and attribute sets containing one or more attributes Ai corresponding to an attribute range. It creates a constant-size ciphertext regardless of attribute count using a non-hierarchical access control policy and multi-dimensional forward/backward derivative functions for comparison.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A new efficient framework based on a Constant-size Ciphertext Policy Comparative Attribute-Based Encryption (CCP-CABE) approach. CCP-CABE assists lightweight mobile devices and storing privacy-sensitive sensitive data into cloudbased storage by offloading major cryptography-computation overhead into the cloud without exposing data content to the cloud. CCP-CABE extends existing attribute-based data access control solutions by incorporating comparable attributes to incorporate more flexible security access control policies. CCP-CABE generates constant-size ciphertext regardless of the number of involved attributes, which is suitable for mobile devices considering their limited communication and storage capacities.

US9705850B2, drawing sheet 1
Sheet 1 of 84

Term

8.5 yearsleft in the term

Expires 8 March 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 3 independent, 12 dependent

  1. 1
    Broadest claimClaim Score 41, average(NHIP)A method of storing encrypted data in a computer based processing system, comprising:generating a public key PK and a master key MK;publishing said public key PK;issuing private keys SKLU and public keys PKLU to each data user, said public and private keys based on the data user's ID and an attribute set LU, the attribute set LU including one or more attributes Ai, wherein each attribute corresponds to an attribute range;receiving a request for a partially encrypted header from a data owner, said request including a specified access control policy Ps;generating a partially encrypted header {tilde over (H)} based on the public key PK, the master key MK, and the specified access control policy Ps;transmitting said partially encrypted header {tilde over (H)} to said data owner;andreceiving a header H and encrypted data from said data owner, said header H and encrypted data being based at least on part on said partially encrypted header {tilde over (H)}.
  2. 10
    An encryption device comprising:a microprocessor;a memory coupled to said microprocessor;wherein said microprocessor comprises logic that executes a method in accordance with claim 1.
  3. 11
    A cloud storage system comprising:a cloud resource, said cloud resource comprising a microprocessor that comprises logic that executes a method in accordance with claim 1;anda hardware computing device having at least one microprocessor that receives data from the cloud resource.